Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89708

In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path ca...
Back to all
CVE

DEBIAN-CVE-2026-89708

In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path ca...

In the Linux kernel, the following vulnerability has been resolved:  nfsd: RCU-protect clcbsession to fix use-after-free on session teardown  After a DESTROYSESSION the per-session teardown path can free a session while rpciod still holds an inflight callback rpctask that dereferences clp->clcbsession.  nfsd4probecallbacksync() flushes clcallbackwq, but once nfsd4runcbwork() has called rpccallasync() the rpctask lives on rpciod; flushing the workqueue does not wait for it.  rpcshutdownclient() does drain rpciod tasks, but uses a 1-second waiteventtimeout — tasks stuck in rpcdelay() (e.g. 2-second NFS4ERRDELAY retries) can outlive the drain.      destroy path                       rpciod     ------------                       ------     unhashsession(ses)     nfsd4probecallbacksync(clp)       flushworkqueue(clcallbackwq)       /* returns; rpctask still live /     nfsd4putsessionlocked(ses)     freesession(ses) -> kfree(ses)                                        nfsd4cbsequencedone()                                          reads cbclp->clcbsession                                          / freed slab */  A second window exists in nfsd4processcbupdate().  When nfsd4findbackchannel() returns NULL because unhashsession() has already removed the destroyed session from clsessions, setupcallbackclient() takes the v4.1 early return so clp->clcbsession = ses never fires and the field retains a pointer to the about-to-be-freed session.  Fix both by converting clcbsession to an RCU-protected pointer:    - Move the clcbsession = ses assignment in setupcallbackclient()     to after rpccreate() succeeds, so it is only published when a     working backchannel exists.  Clear clcbsession on the error     return in nfsd4processcbupdate().  Both stores use     rcuassignpointer().    - Annotate clcbsession with rcu.  All rpciod-side readers use     rcureadlock()/rcudereference() and check for NULL, bailing to     the appropriate error or requeue path:     encodecbsequence4args(), decodecbsequence4resok(),     nfsd41cbgetslot(), nfsd41cbreleaseslot(),     nfsd4cbprepare(), and nfsd4cbsequencedone().    - Switch _freesession() from kfree() to kfreercu() so the     session slab is not reclaimed until after an RCU grace period,     guaranteeing that rpciod readers inside rcureadlock() never     dereference freed memory.    - Pass the session pointer to the nfsdcbseqstatus and     nfsdcbfreeslot tracepoints instead of having them re-read     clcbsession.    - nfsd4cbprepare() calls rpcexit() when the session is NULL,     routing through the done/release path to requeue the callback.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89708

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.111-1,7.2.6-1,6.12.111-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading